AZ-700 exam dumps

AZ-700 practice question 113 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 113

Select 2

Your company hosts an internal line-of-business web application on Azure App Service with Azure AD configured for authentication. A user on the corporate network reports that the sign-in page never appears, resulting in an HTTP 401 Unauthorized response. Preliminary application logs show no tokens being requested from Azure AD. The network team suspects traffic to Azure AD endpoints may be blocked or incorrectly redirected. Which two actions should you take to diagnose and resolve this issue?

  1. A

    Verify that DNS resolution to Azure AD endpoints (such as login.microsoftonline.com) is successful and not blocked by internal DNS or firewall rules.

  2. B

    Check the client machine� system clock and synchronize it with a reliable NTP server to prevent token validation errors caused by significant time drift.

  3. C

    Configure a Managed Identity for the Azure App Service to bypass the need for Azure AD authentication tokens from client devices.

  4. D

    Create an inbound NSG rule allowing inbound traffic from the corporate IP range to the Azure App Service.

Show answer and explanation

Correct answers: A, B

Explanation

The most common causes of no sign-in page appearing are network or DNS blocks preventing requests to the Azure AD sign-in endpoints. Verifying that corporate DNS and firewalls allow outbound traffic to Azure AD is essential. Additionally, ensuring accurate time synchronization on the client helps avoid token validation failures due to clock skew. For more information, refer to Microsoft� troubleshooting guidance at https://learn.microsoft.com/azure/active-directory and best practices for DNS and firewall configuration in Azure.

  • A. Correct.

    Correct. If internal DNS or firewall settings block or incorrectly resolve the Azure AD endpoints, the user cannot load the Azure AD sign-in page. Ensuring access to login.microsoftonline.com and similar endpoints is critical for successful authentication.

  • B. Correct.

    Correct. Even small mismatches in the system clock can cause Azure AD token requests to fail. Synchronizing the client machine� clock with a reliable NTP server helps mitigate token validation errors.

  • C. Incorrect.

    Incorrect. While Managed Identity is useful for service-to-service authentication within Azure, it does not resolve client-side issues where a user is unable to reach Azure AD for token acquisition.

  • D. Incorrect.

    Incorrect. An inbound NSG rule affects traffic flowing into Azure resources. In this scenario, the user needs outbound access to Azure AD endpoints. The 401 error and missing sign-in page typically indicate an issue with reaching Azure AD rather than inbound rules to the web app.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam